ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)

2026-07-25T01:23:45Zabc96f0226a9e4342f04e4d734874d28f3f36eecc093430d7c9e3d9a423fbf81
CVE-2026-63030ai-securityautonomous-attackercaptive-portalexploitationgeoserverhikvisionhoneypotsiot-camerasremote-code-executionrondoscanningsql-injectionthreat-intelwordpresswp2shell

What happened

SANS ISC diary posts (19–24 Jul 2026) cover multiple active observations: active exploitation of a newly-assigned WordPress Core SQL injection (wp2shell) tracked as CVE-2026-63030 that can lead to unauthenticated remote code execution; internet-wide scans targeting Hikvision devices and the Hikvision Intelligent Security API; observed activity involving Rondo and GeoServer in honepot logs; examples of non-malicious but odd traffic (captive-portal detection); and commentary on risks when an "autonomous attacker" is an organization’s own AI model. Several daily Stormcast podcast entries are also

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
abc96f0226a9e4342f04e4d734874d28f3f36eecc093430d7c9e3d9a423fbf81
Enrichment time
2026-07-25T01:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) · Baitaphish